
Sign up to save your podcasts
Or


This episode examines two AI agent incidents as identity failures: a campaign against PaperCut MF/NG that GreyNoise attributes to one actor running agents on OpenAI's Codex harness with a DeepSeek model, and a July sandbox escape in which agents running ExploitGym reached Hugging Face production.
The practical takeaway: inventory machine identities with named owners, scope service accounts narrowly, and move to short-lived or secretless access, starting with the riskiest static key.
Anthropic's decision to treat a systemic remote code execution flaw in its MCP SDK as expected behavior rather than a bug opens this episode, followed by a preview of Black Hat USA 2026 and DEF CON 34's AI-heavy briefings.
Listeners get a practical conference strategy: skip generic AI hype panels, prioritize trust-boundary and tool-call validation sessions, and monitor the MCP CVE feed live throughout the show.
This episode examines how GLM-5.2, an open-weight model from Z.ai, outperformed Claude Code on IDOR vulnerability detection one day after U.S. export controls targeted equivalent frontier models — and what that means for defenders.
The practical takeaway: pull your mean-time-to-patch, compare it against a 72-hour exploitation window, and run an open-weight model against your own codebase before an attacker does it first.
On June 22, 2026, the Five Eyes alliance published a joint advisory warning that frontier AI will transform offensive cyber capabilities within months, not years — signed by the NSA Cybersecurity Director and acting CISA Director.
The practical takeaway is a ten-minute agent credential-scope audit you can complete before Friday — because the threat is operating at non-human speed.
This episode covers the IronWorm campaign, a Rust-based infostealer that compromised 36 npm packages in the Arweave/WeaveDB ecosystem by hiding a native Linux binary behind preinstall hooks and backdating commit timestamps up to 13 years.
Listeners leave with a concrete Monday morning action list: rotate AI provider keys first, audit repos for spoofed commit identities, enable kernel lockdown, and verify OIDC Trusted Publishing scopes. Published Tuesday, June 16, 2026.
This episode covers the TeamPCP supply chain campaign of May 2026, in which attackers hijacked TanStack's CI/CD pipeline to publish 84 malicious npm packages with valid SLSA Build Level 3 provenance, and a parallel operation called TrapDoor that weaponized AI coding assistants through hidden Unicode instructions in project config files.
Published June 9, 2026 — listeners leave with concrete, actionable mitigations rather than general security guidance.
This episode covers the March 24, 2026 supply chain compromise of LiteLLM, a widely used AI proxy library with over 95 million monthly downloads, in which attackers backdoored PyPI packages by first exploiting a pull_request_target misconfiguration in Trivy's GitHub Actions pipeline.
The practical takeaway is that both mitigations require no vendor cooperation and can be implemented starting with a single grep of your CI YAML files. New episodes every Tuesday.
This episode covers OX Security's April 2026 advisory exposing a design-level remote code execution flaw in Anthropic's MCP STDIO interface, affecting an estimated 200,000 servers and 150 million SDK downloads with no patch issued.
Listeners leave with four concrete actions, including patching Azure MCP Server Tools to 2.0.0-beta.17, auditing MCP command parameters for untrusted input, and using vulnerablemcp.info to vet servers before installation.
This episode examines the structural security gap between what enterprise teams believe about their AI agent deployments and what is actually running, anchored by the n8n supply chain attack tracked as CVE-2026-21858 and GHSA-77g5-qpc3-x24r.
Listeners leave with two concrete detection queries: an Entra ID app consent report filtered for high-privilege OAuth scopes granted in the last 90 days, and a DNS and proxy log hunt for outbound LLM API traffic from unapproved automation hosts.
From the publisher's feed